Reconciliation
In a reconciliation, Nova compares what is intended for an identity with what actually exists in the target system. Nova shows the differences; they are resolved deliberately, in one direction or the other. For a single identity, the “Reconciliation & Provisioning” tab shows the differences per target system.
Leading side
For each target system, it is configured and visible which side leads: Nova or the target system.
Only complete reads count
Reconciliation and imports act only on data that was read completely:
- If a target system returns its results page by page, Nova reads through to the last page.
- If a read remains incomplete – because of an error, a timeout or missing read permissions – Nova changes nothing and marks the result as incomplete.
What an import never removes
An import never removes assignments that are still pending, start in the future or come from an approved access request.
Validity counts
Nova never shows an expired or not-yet-valid assignment as “In Sync”.
Changes made outside Nova
If someone changes a target system directly, Nova detects the difference the next time it reads the system and shows it with the time of the last read. Administrators resolve it deliberately, in one of two directions:
- take the target system's state over into Nova, or
- restore Nova's intended state in the target system.
Bulk actions first show a preview of exactly what will change.
The change journal records only what Nova itself has written. Changes made outside Nova become visible through reconciliation.